#koth
1 messages Β· Page 38 of 1
What's with the port 61432? mentats
i think that's not min
What's with the port 61432? mentats
@ornate token node service moved to that one
mine* @ornate token
instead of 3000
Downvote all you want, I'll get that nitro and spam you with this pepesaber.
I see... no response from it xd
@tepid hornet π
@nova tide osint
@nova tide
I see... no response from it xd
@ornate token try port 65531
we can do another one if you all want
Nothing
I'd enjoy another game :D
@ornate token is random room ok to you?
Ye, I'm familiar with none of them so Β―_(γ)_/Β―
dont make hackers.
when will hackers be removed?
??
Lmao, why would it be?
why it is going to be removed?
It's one of the only epic machines
isn't there something like a monthly rotation?
Ah, no, they will keeping adding to them.
So after one point people will not be able to keep specific notes for every machine
except for those playing from the beginning

@nova tide fortuna pass has been changed?
yeah
yeah
any hint?
Ye, idk what to do with it
what? base64?
Ye
that has already patched but
look for "file signature"
you get something pretty strange decoding that base64
np
that's a nice way in, I liked that
but @nova tide already changed that password π’

He's rlly playing r6 xd`
And he's winning 
that's how it works when someone knows how KOTHs works
did you find something else?
i know the nfs and base64 ways
Aside from that port, nothing
i'm feeling dumb
gobuster found nothing
is there any port upper than 10000? @nova tide
i can't do -p- scans because my internet is so slow...
well i just somewhat patched the way coz gobuster won't find the directory
so all the 4 methods ik are already patched π€·ββοΈ
well GG hahah
even if you get in, all the privescs are patched.
even you privesc my king loop is running.
i think it's pretty much useless unless there is no way in
Let's reset x)
I was joking, but k
yeah reset and try finding that third way in.
imma get some sleep. just registered for summers
well good night π
well its 04:15pm π€·ββοΈ
Cya!
cya
@ornate token reset?
Yeah, still stuck
Ye, cyberchef did the job but searched anyway. Further on idk
you are getting something like ..PK.. ..... from base64
Yes, cyberchef detected the file
You can dm anytime, I'll try harder a bit more bfore giving up
first time I ll play KOTH
anyone up for a koth?
yeah
hello
@forest bobcat false
why?
The shell is a file on the box
my terminal got breaked with random stuff
Still applies
Attacks to your machine are not allowed
ok
Spamming shells that you have on the box is allowed
Take a minute to read the rules
ok thx sir
Please don't address me as sir.
lol
hey?
need help regarding koth here... i am connected to the vpn and can ping the box ip, but cannot access it via browser or run an nmap on it or anything.. Does this happen when it is under load or something?
i confirm you from my side is ok... able to connect and interact with the machine
i am though.. tried killing openvpn and reconnecting but that doesn't fix it..
kindly note that i am able to ping the ip though..
Stuff that relies on your network connection to the box
Your network connection to the box is your VPN
did you get the root
checked my internet and my connection.. it's all ok..
why when i go to ip/wordpress/wp-admin in panda machine it doesn't work
hi
can any one help
@visual spire try to add the ip address to /etc/hosts and call it panda.thm
by the way, does anybody know how to access another user's terminal when you have root?
somebody wrote exit on my terminal and Im wondering how
i would greatly appreciate anybody's help! π
your terminal is linked to a pseudo-terminal (pty) and as almost everything else on Unix-like OS, it is available as a file
namely /dev/ptyX
also, your shell has your stdin available as file descriptor 0, available in /proc/<SHELL PID>/fd/0
thank you so much!
welcome π
(google for how to get reverse shells using wordpress)
you can edit the 404.php in themes editor to execute a php reverse shell
but there are many different ways
thanks
youre welcome!
anybody wanna play koth with me
anyone here?
Anyone up?
anyone up????
lol
KOTH play???
In KOTH is there any other way of checking others tty other than who -u
is other koth players are in active in current game?
I need to check it
No one submitted any flags there
In KOTH is there any other way of checking others tty other than
who -u
@serene bayps aux | grep pts
Orw
hello there! im new here and i would like to spectate someone play kotk as i find it really interesting, can someone send the spectate link here if somone is going to play ?
@visual spire you can try to exploit wordpress installed plugins
many plugins are vulnerable
i did it
thank you
wanna play__
??
yes
@patent forge Haha gg you're trash
@gusty rapids yep
or maybe you can't even read a linpeas output properly?
i've patched 3 suid, nothing else π

π
@glossy vessel imagine crying for luck parameter and suid patches (i didn't even touch the luckyshell) on fortune
that's the point
@patent forge Haha gg you're trash
@gusty rapids but this is not learning.
you could ask for a hint @gusty rapids
haha
what a kid..
i will
yeah
you're trash
that's not acceptable
ah nah he played well , not an insult
Please keep it civil though.
relax guys i just say gg @patent forge and trash not in the bad way , sorry if it hurts someone !
why are you all asking to reset the machine? we did that like 8 minutes ago...
Didnt even see we had a reset
same
guys wtf stop resetting pls
my gosh.......
well, now we know when we play against you what the root password is
this make no sense
lol
you can't stand loosing
@livid dagger yep, common user is yormoma
lol
if you find that, that's me β€οΈ
π
https://tryhackme.com/games/koth/8303 - Whoever is wanting to continue, there is still one vuln left open
just saying for if you want to defeat me
to let me try finding the last vuln β€οΈ
fine
there's only 1 hole
Which machine?
Ah, ATB.
@stiff egret @livid dagger this is the only problem with space jam
there is only one hole
port 3000
who so ever will patch that method will win
@livid dagger has it something to do with carrots? π
yef node js
carrots?! that made me laugh sorry
there is only one hole
@zinc furnace There are multiple methods in the box.
no, nothing to do with carrots
carrots?! that made me laugh sorry
@livid dagger /local
@zinc furnace No, there are at least that I have been able to figure out, 2
don't know what you mean
DM me if you have to
There are 3 methods in the box, I think.
the telnet is vulnerable ?
π€¨ Maybe
@stiff egret carrots? π₯
π€
Actually I am not playing rn, solving some box. So, I don't know If I'll be able to help much. Anyway, I can try π
starting in 5 minutes
start in 23 min
@formal kindle that's a spectators link. click on "Options" from top right corner and copy the invitation link
@patent forge hahaha nice man
β€οΈ
that was actually fun
we have 20 minutes left
link ?
Im not too good on the protecting bit lol
me too
me either
is there anything on that side ?
like blog or video
when you changed the king i gave you some time before killing everything
hahaha
@formal kindle there is the link up there
https://tryhackme.com/games/koth/join/3fb9f54c22cd58122969c35c
@patent forge -
?
nothing patched, just moved stuff π
lol
nope
upload still working
and someone else patched ssh key
before i actually write my "sign" into the txt file
gg guys, I have to leave, nothing patched by me except from gdb which has moved to gdb2 keeping SUID capatibilies
i use gdb2 but i loose my shell and someone patch shrek ssh private key π¦
how rude
Its not rude. Its called competition
hi
GG
Anyone up rn? π
yep
public one
@sturdy plank
@sturdy plank did you patch everything alredy ?
i think he is just killing all pts
@sturdy plank did you patch everything alredy ?
@fair adder yes
except ftp anonymous login
what's the point of playing like this? π’
there is no point tbh
Elf do you know something about the port 9002
let me see
telnet that
you get a limited shell
but if you write more than some characters you get a "segfault"
yeah i se
doing a echo $(ls) i'm getting "koth" as file
i cannot do "pwd" because of segfault
echo $(id)
@patent forge those commands do not need to be wrapped in an echo command π
of course i know
i changed permission
we are in a shell which doesn't give output
so i dont think u can use any command except cd
so i have to echo that
if the limit on the command was 1 char longer i would be able to make a script to execute whatever you want via that port
why u guys reset
could you pass me the IP? π
because you fucked the machine β€οΈ
@sturdy plank what is the point of playing if you have automated scripts?
i dont
so you got in and manually patched everything in less then 3 mins ?
so you got in and manually patched everything in less then 3 mins ?
@fair adder yes
nah i give up i don't want to play vs ppl that have scritps
i mean it's production so it's easy to patch everything
it's not like there are that many ways to root it
ashu@10.10.20.38's password:```
why this happening
nah i give up i don't want to play vs ppl that have scritps
@fair adder i dont
Because you need a password for the account
the key isn't there :)
@sturdy plank and i thought that was you lmfao
or someone regenned keys
yup
key is here
or someone regenned keys
@full grove
maybe
not maybe, yes, I can almost guarantee thats what happened
rm ~/.ssh/authorized_keys && ssh-keygen
but nobody get king
so it should be a problem
restart???
ok
now someone get the king
but they against rule
lmao
they reseted the machine when i patched most of the things @grand ember
and?
u laught at wat??
that's how most public games look lmao
hmm
Mr they patched one way
i thought the admin add the rule that dont restart machine when the paths are patched
and they are NOT killing all pts
so what's the point of this?
but they against rule
@sturdy plank
if you can't even do anything
i thought the admin add the rule that dont restart machine when the paths are patched
@sturdy plank lmao why would they, the reset is vote-based
patching a id_rsa key is not cheating
it's called hardening the system
i didnt say its cheating
i don't think so

it's too easy to find
there is a root shell on the 9002
just trying to use that (i think i got the point)
9002 is useful but to use it effectively you need to have a user shell in the first place
also oyu can just kill/stop 9001/9002
there is but it's tricky to get it working
is it bof?
no
WT*
i was thinking to do something like e=$estuff
in a while loop, keeping it under the lenght limit
trying to set a reverse shell command
why people vote for reset while i patched all
the machine didnt destroy
or nothing happend to it
but they vote for reset
WT*
ok any-way
And I got kicked out immediately
why people reset while the machine didnt destroy
That was a problem, not the ssh key
or nothing happend to it
Have to wait 1 minute
I waited about 5 mins now
So you are not king
yeah i know but i think the service is corrupted
Post a screenshot of catting king
starting in less then 5 minutes π
echo "slavkosmith" > king.txt
bash: king.txt: Operation not permitted```
i hate carnage...
chattr? @fair adder
@patent forge it says chattr not found as a command
and i found it
and when i supply full path
it still doesn't work
this is pain
no i was asking that because of the operation not permitted
yes you can
you can get your name in there in two ways
one requires chattr and is effective
it doesn't have chattr π
one doesn't require chattr but may not work if someone is already in that file
then upload chattr duh
anyone playing rn?
@fair adder can you helping me with installing chattr if someone uninstalled that?
oof
if it's not a static version of chattr it might not work because of different lib versions on your os and the box
anyone up?
nah, i'm left
wdym
if it's not a static version of chattr it might not work because of different lib versions on your os and the box
basically the version you normally have in /usr/bin or smth is a dynamically linked one
it might work but it's not 100%, it all depends on the linked libraries it has and if they are present on the box
that's why you'd usually upload a statically linked one
yeah its a good point
any hint on tyrell? (except from librenms)
Public Game starting in 20
any hacker want to play koth??
public koth starting in 7mins
@visual spire good luck π
vm?
why is people voting for reset???
my god guys, nothing patched except from ssh key
there are more ways in.
if you reset i'm gonna patch it anyway
@visual spire are you playing now?
yes
π¦
@patent forge seems you in again
noope
didnt patched anything this time
and i also tryied a new way in
(check upload on port 80 and try common formats)
some one patched it cuz i cant get the rsa to work
there are other ways.
stop focusing on that
that is a simple vulnerability which gets immediatly patched when used
lol i tried 3 that i know
in this case, odestorm just removed authorized_keys
i used the upload form, and it worked.
the upload page never worked for me
it actually work
upload what exactly π
he is asking for an image
try some images format
gg for odestorm which patched the id_rsa after asking for reset because i did the same π
i found another way for shrek
telnet?
another public one π https://tryhackme.com/games/koth/join/eea228a9313c9dbecaa25e75
Is patching id_rsa the equiv. of changing the locks on all the doors (Defeating the "Leave services available to the normal expected users of teh system" requirement?)
Is patching id_rsa the equiv. of changing the locks on all the doors (Defeating the "Leave services available to the normal expected users of teh system" requirement?)
@inland sluice is there another way? so no.
No, you can clearly patch ssh by changing rsa-keys.
When you change passwords or keys for a user, you'd give them the new key
I don't think that illegal(?)
Changing keys is fine
Switching ports it fine
Changing the config to only accept keys is fine
When you change passwords or keys for a user, you'd give them the new key
@quiet schooner wdym?
@stiff egret do you know something about lfi on lion 5555?
There's a security breach, and your keys and passwords have been leaked. here's new ones @stiff egret
The only thing that isn't fine is just shutting the whole thing down
Oh
@quiet schooner?
@terse willow DoS, allowed hosts etc
Swear that's forbidden in the rules
That falls under a different rule..
There's a security breach, and your keys and passwords have been leaked. here's new ones@stiff egret
@quiet schooner Why would I change them in first place, If I give it to them later?
Eh, I reckon allowed hosts would be fine too, to be honest
@stiff egret Real world situation, you change keys and then give the genuine users the new keys
It's a real world thing
@terse willow You're not allowed firewall rules, so that seems pretty similar to me
I'm just trying to understand what i can/cannot do re: koth, only done one of them so far
Nothing to do with the firewall though, and if you've changed it to keybased authentication and changed the keys then you've already accomplished the same thing
@stiff egret You don't give the attackers the new keys
π€¨
What about say .. doing privesc and enabling f2b on the host
@stiff egret If there's been a breach, the IT department change the SSH keys. They give the new keys to the employees -- the genuine users of the system
@inland sluice Can I ask if you've actually read the rules?
How is it different than hosts/changing the keys? As for reading the rules, I am. because i am evaluating your responses against said rules to determine the brown score
...wat
That's a point actually. @lusty portal can you clarify this in terms of KoTH rules -- are you allowed to bump up the security measures around SSH?
i.e. change the Allowed Hosts, add fail2ban, etc
I don't see why not?
It's technically realistic
Its all about attacking and defending
Yeah, that was my thought
Although
As long as its not full on stopping the service
Fail2ban updates firewall rules
So, apologies @inland sluice, I was right with the hosts, and wrong with the f2b π
Which are banned
Fail2Ban is able to reduce the rate of incorrect authentications attempts however it cannot eliminate the risk that weak authentication presents. Configure services to use only two factor or public/private authentication mechanisms if you really want to protect services.``` @terse willow
Yeah hm. Once you're banned from talking to the host, its game over.
Will add to my list of things to discuss with Ashu and get back to you on that.
I would say that it's one of those things that can end a game very quickly indeed
Isn't that almost equal to iptable ban?
So can changing a ssh key?
Configure services to use only two factor or public/private authentication mechanisms if you really want to protect services. Literally tells you to just enable key auth and not bother @terse willow
So possibly shouldn't be allowed based on that
@stiff egret it's a timed firewall rule, it's exactly equivalent
I mean, yeah, there are definitely better ways James π
So can changing a ssh key?
@inland sluice Changing SSH keys is definitely fine π
π€·ββοΈ
re: changing keys is fine. is that because multiple vectors exist to obtain either the key, or to supress/change it?
Each box has at least 3 entry points
Or should
I was told 4 for Fortune π€·ββοΈ
So, yes, that's the idea. Once you get in another way, you can change the SSH keys back
re: changing keys is fine. is that because multiple vectors exist to obtain either the key, or to supress/change it?
@inland sluice Changing keys is fine, because that's a legitimate measure
In the end, you're looking to do realistic stuff
the legitimate measure part confuses me,
You're perfectly allowed to get on the box and patch all the vulns immediately
People will get mad and reset the box
But you can patch everything. But don't just drop heavyhanded firewall rules
Patch intelligently
Fix the actual issues, the logic flaws, the broken code, the exposed creds
Basically, if you're doing something that would stop the box from functioning normally, then there's a problem. Think about it in a workplace environment -- if the box needs SSH, then SSH has to exist.
@inland sluice There's also no such thing as a "brown score" π
@quiet schooner Sure there is.
It's a polite acronym for the opposite of an "it factor"
I'm pretty sure you're making up terms now
Be nice James π
What do you mean by brown score @inland sluice? π
@quiet schooner "it factor" urban dictionairy, i didn't make it up
Bluntly, its could probably slip past a PG-13 censor, as long as it didn't also feature bikini's, death, violence, drugs, or any other adult themed content
Brown factor .. in this instance, brown is a synonym for a word that rhymes with "it"
Sorry, but how does that relate to reading the KoTH rules? I should very much hope they don't contain violence, nudity or adult content
It does not. it has to do with anyone interpretation/explaining anything. It's the "Are they full of 'it' " comparison
Does anythign they say directly contradict the "rules" they are bringing up
Yes that's snippit, and yes i botched the snip initially with hi-liter
Urban Dictionary is a joke
My question for KotH is, should the defenses applied be realistic, as in used during Incident Response, or is further destructive and counter-productive measures allowed to fend of further intrusion?
You shouldn't be doing anything destructive for the most part
I think they have to be realistic, otherwise just use iptables and block all ips except your own π€
I've never played it, but from what I can hear, is that it becomes more a game of defeating offense with better offense, rather than applying realistic defensive measures.
It depends on who you're playing against
Because I just patch the box completely
Which makes it no fun for anyone else, and they spam resets
Give points for proper realistic patching, would that be an idea to promote incentive to realistic defenses?
Probably
But how the heck do you automate that? π€£
Be a bit difficult to determine what counts as "realistic patching" on the fly
do old exploits work, is the service still up
I believe a few of the attack defence CTFs do this
Yeah, probably through some probe script.
So, basically, probe services to see if they're still up? Which is essentially health checks, no?
In that case, who gets the points? You'd need to be monitoring the bash history of each pts, in real time
Sysmon π
The only way I can see of to get it working would be to have a whitelist of "realistic" fixes for each service, submitted by the creator, which means you could potentially miss some
And even then you still have the problem of not knowing which user account to give the points to
imo, too much for a 1 hour game.
Even if you could match a fix to a PTS, you then need to match it by account
Which is doable with IP, I suppose, but that's some serious scripting on every box to get it working π
Would be a great idea though
Just use socat. π
Socat fixes everything! π
But how the heck do you automate that? π€£
@terse willow apt-get update && apt-get upgrade? (yum -y update? )
one cmd patch
To automate monitoring the logs to see which user applied a realistic defence?..
Umm .. send syslog somewhere else. add it to the "do not mess with this port" ip
Now filter on that host for reasonable/unreasonable
Which is a good way to see a realistic defence being added, but you have no way to link it to which TryHackMe user made the defence π
Umm...sure ya do
Uh, how?
When you connect to ovpn
your mac address and ip address are bound
If you think they aren't mining this info for something ... π

So, what, the IP address is going to be linked to the user account making the connection in the syslog?
Bear in mind, that's a syslog, for reference
It'll tell you the user account that ran the command (and doesn't actually store every command either)
But doesn't link it to a PTS. Even with the PTS, you'd need to link that to an IP
Although you're right, we can link IPs to users π
There's a reason the King service works the way it does though -- by entering your exact THM username into a file on the machine
You can link a PTY To an ip
you can link an ip to a user.
You can link a cmd to a pty
It's impossible to tell who's king without it
How do you intend to link a command to a pty in real time? π
(Serious question -- if there's an answer to it, then it could be great for Koth)
i do something very close to this w/ graylog
The query shows the sessions, and the users. as for the linking a cmd to pty. have you ever seen top (V) or ps -auxfw
there is already a chain for processes parent/child
And where exactly is that getting monitored (and with whose resources)?
Do you mean where I am doing graylog? please be more direct
No, the process list
ps auxfw example
Which is great, when you're on the machine
That would have to be part of a nanny script.
It would be easy to do if these were all dockerised
Thing is, they're full VMs
So you're gonna have to exfiltrate that list somewhere, in real time
Preferably encrypted
Yes, you will. you will have to set up a loghost
BUT chances are, such a thing already exists
so application -> syslog err -> syslog host
it could be err, info, whatever level you specify
apt-get install auditd
auditctl -a task,always
ausearch -i -sc execve
at a system level, to trap the input
I am pretty sure nesting only goes one way though, you cannot log TO a container from host.
but that wouldn't serve much purpose anyhow
.... Our windows systems generate 18GB/day / host π¦
noisy boxes
@terse willow If you are earnestly looking for a way to apply it to your vm infrastructure, i can offer to help you with a way to integrate it
It should not matter, if its host, guest, lxc, docker, vagrant or ansible .. it should apply just the same (see the post setup cmds pasted above)
Could well be worth speaking to @lusty portal about that -- it would be him that needed to set it up at the site side to receive any information. Skidy, is this type of logging something that's possible for Koth?
Anything is possible. (If you can coherently describe what you are trying to do, you are over halfway to doing it) you are setting up a kernel level daemon to monitor syslog, and trap activity in it. I think a better question is, is it DESIRED
More on the auditd approach: https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/security_guide/sec-understanding_audit_log_files
5 min food
please don't do patches im making notes for each room so i can sound like a pro
Elf
yes
Warmup Game starts in 9
@forest bobcat were you bro ?
shit
hey!
stop making fake king.txt
Public Game starting in 20
@serene bay I just woke up, give me 5 minutes
Time for a coffee and a cigarette and Iβm there
Yah I'll come later gotta finish some 100 episodes today π
I NEED ANSWERS I DON'T NEED TO REST.
well
i just rooted the box

@patent forge how does it feel when you can't do anything ?
i'm working on 15065
Ν
but it feels good if people are good π
even if you get shell you can't do anything xD
yep, but i'm learning something new
i'm a total beginner, i started studying like 2 months ago
i think that is pretty normal beeing keep closed out from people who just knows passwords
i had to scan, find the image, extract data then moving on mysql, guessing password and so on
of course if i've alredy known creds, you would be the one out π
i dont know passwords π
i'm talking about the other guy π
i had creds in 3 minutes, but he had already changed that
jesus
π
wasn't everything patched?
even if you get shell you can't do anything xD
@fair adder
it wasn't
i just locked everything up
yes
at that time
i was sitting and waiting for you to come
now i'm waiting you β€οΈ
pleeeeeease
idk how you are better lol
used the cmd thing on port 15065
im 2 lazy to remind my self what its called smh
yep i did, but it needs a bit of js knowledge
so you need js knowledge to read the uri π
eh ig
yep, but the uri is obfuscated dude
maybe yes hahah
π
(just nice competitivity, nothing against you)
i don't even know if i wrote "competitivity" right lol
smh its alr you deserve to win anyway
@fair adder yep, you are right XDD
found every way on this machine before getting in
Tyler's ssh is borken
tyler
BeenReset thrice still so slow
wdym ?
oh jesus you dont know π
ah i was thinking something else π€£
yeah tyler is preety easy
i used to think its hard until i tried it on my own
like without anybody
not very hard.
it just needs your name in there then boom
yep π
@fair adder you wanna come one ?
@serene bay cant rn im busy fixing my pc so i can play league
prioritiesπ€
rn no prioprities cuz it died..
@fair adder won for 5 points
you really could no nothing btw, i've patched the post call
ggs btw
yes but when you got king i had the shell
i could have killed you instantly if i wanted to anyway
but gg π
@patent forge up ?
i could have killed you instantly if i wanted to anyway
@fair adder you can kill pts's instantly
i don't think you had a top open (you dont.)
@serene bay glhf β€οΈ
it's open
internet trouble π©
no way π
there is no problems with machine.
imma leave you frustated me
@serene bay i got frustrated too when peole resets machines just for the ssh key on shrek...
my internet's damn slow rn idk
who is zezuz ???*
Good Game
is there a no-bruteforce way in hackers?
dm me if u want to get more @patent forge
2 waiting in KoH
public one in 19 mins https://tryhackme.com/games/koth/join/56b4e0226db45e9a99f00f1c
can the windows box be last?
they're ordered by the time of addition
@grand ember In reverse order
π
Remove Windows 
windows is malware
π
can developers of machines add new machine to it??
What?
nothing
@quiet schooner @full grove Iβm working on a room, but I would be glad to work on a KOTH room too
Is that possible?
KOTH boxes are usually made by special creators with an admin approval
So I guess, If you really want to make a KOTH box, it's better to catch some admin (Dark for example) in the general chat and ask him directly
@sturdy plank You using my name in the koth ?
@inland sluice wat u mean??
Thats why i was asking if you stuck my name in the root flag file or something π
That + 3 king changes
New KoTH machine when? 
Every month new machines will be added to the pool, this will help reduce the chances of playing the same machine repetitively.
Soon or maybe soonβ’οΈ π€
If we get another KoTH machine before we get socks there is going to be anarchy in the streets.
Others are not fun anymore π€·ββοΈ
Cryillic is busy i think π€π₯Ί
Whaaaaat
@patent forge whats up?
@fair adder π
@fair adder i'm not playing lol
time to get root
nononono
have you changed the passwords?
i think there might be one other password left unchanged
actually i'm pretty sure there is

wow @austere wyvern a reset should of course let you win!
gg for your competitivity and for not beeing able to check cron jobs before asking for a machine reset β€οΈ
wdym
so that's something that needs to be addressed eventually and is 100% a valid concern
replayability it difficult to implement, especially in a KOTH-On-Demand esq service
and I'll toss that into ideas chat π
naming machines give possibility to just "google <machine name>". Just don't give name to machine can be a first step
@fast oyster That's been brought up. You can identify what machine it is immediately on getting your nmap results, so it doesn't change much
I mean
You just have a super quick table
if this port is open, it's Food etc
Bear in mind there are also people like Naughty or Donuts around
Who can likely identify them all at a glance of the results
Is there any harm in trying a game of KoTH if I know I dont have much experience
Just to see how it is
2 of the KoTH boxes are available as standalone rooms
So I'd recommend that first
Thank you!
I don't get KoTH goals, name of the machine is written and all writeup are on the net. people just google, follow walkthrough and patch everything ?
@fast oyster the only available writeups for koths (at least that I know) are the @stiff egret βs, which tells you the easiest way of (at least) every machine
The point of koth is getting better with tools and techniques which you already know, getting more comfortable with your setup, and learn Linux sysadmin techniques also by other players
Oh. @trim sand
I forgot about the hackers one, but this is the only one I knew
Also when I play I always try to find new ways in before using the one I already know
Discord won't let me send a link that happens to have a channel name in, because it's broken. But the message above has a link that will show you the two rooms
Yes I have to look for βkothβ in activities
Btw I got your point too
Sometimes is so annoying finding skiddies in KOTH
@sudden condor gg
you too mate
@vagrant gull Ayyy
@sage kindle
hhahha
We're all in a Discord call hanging out
We're all in a Discord call hanging out
@dreamy wasp where π
There is also a KOTH vc in this discord as well.
Ok thought you meant privately
@nova tide We were in our own Discord call, thought we'd do a box with just the three of us and wound up joining this fella instead
Wanted to track him down on Discord for a gg message c:
Didn't know there was a koth vc, I joined the Discord about 2 minutes ago
@nova tide We were in our own Discord call, thought we'd do a box with just the three of us and wound up joining this fella instead
@dreamy wasp oh the game where there were 4 australians playing tyler?? π€
Yep
4 in total
aah i just saw that game but i didn't knew any of them.. i was planning to ping someone to send me the invite link π


